Huntress reported a macOS intrusion in which a user searching Google for Claude installation instructions clicked a sponsored result that led to a weaponized public Claude share on claude.ai, ultimately triggering installation of MacSync, a stealer and remote-access trojan. The infection chain relied on a pasted command executed by the victim, then fetched a server-side AppleScript payload, prompted for Full Disk Access, and harvested browser data, keychain contents, wallet information, and other credentials before installing a persistent Mach-O RAT. Investigators said the malware also deployed a helper component to obtain Screen Recording permission, expanding the attacker’s visibility on the host.
The campaign used delivery domains agenticsora[.]com and malwareaudit[.]com, a RAT command-and-control endpoint at 85.206.161[.]241:8443, and seed-phrase collection domains main.sdhomeinspectors[.]com and main.southcarolinacounselor[.]com. Huntress found that if cryptocurrency wallet applications including Ledger Live, Ledger Wallet, or Trezor Suite were installed, MacSync trojanized those apps in place to phish recovery seed phrases and exfiltrate them to attacker-controlled infrastructure. The researchers assessed that MacSync shares strong lineage with AMOS/Atomic Stealer tradecraft, including Russian-language developer artifacts, but goes further by combining credential theft with persistent remote access, screen capture, and wallet-app rewriting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Huntress published an analysis of a macOS intrusion in which a victim searching for Claude installation instructions clicked a sponsored ad, opened a weaponized public Claude share, and ultimately installed the MacSync malware. The report detailed a six-stage infection chain, persistent RAT functionality, screen-recording abuse, and trojanization of cryptocurrency wallet applications to steal seed phrases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cyberaccord.com
Open sourcecybersecuritynews.com
Open sourceitsecurityguru.org
Open sourcehuntress.com
Open sourcecert.gov.az
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.